Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Vadymsoroka

#42164of 56,336
6.8Total CVSS
Vulnerabilities · 1
PT-2021-14424
6.8
2021-03-08
Glpi · Glpi · CVE-2021-21327
**Name of the Vulnerable Software and Affected Versions** GLPI versions prior to 9.5.4 **Description** The issue allows a non-authenticated user to remotely instantiate objects of any class in the GLPI environment, potentially leading to malicious attacks or the start of a "POP chain". This affects the integrity of the GLPI core platform and third-party plugins runtime, particularly those with sensitive operations in their constructors or destructors. **Recommendations** For versions prior to 9.5.4, update to version 9.5.4 to resolve the issue. As a temporary workaround, consider restricting access to sensitive classes and their constructors or destructors to minimize the risk of exploitation.